Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'CTFM0N' = 'c:\R217625wabc217625\MUpdate.exe c:\R217625wabc217625\Qaekj.dll,ALSTS_ExecuteAction'
- 'C:\R217625wabc217625\MUpdate.exe' "c:\R217625wabc217625\Qaekj.dll",ALSTS_ExecuteAction
- 'C:\B00T\BigFilePluginSetup.exe'
- 'C:\B00T\806.exe'
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 3
- '<SYSTEM32>\cmd.exe' /c ""C:\B00T\run.bat" "
- %TEMP%\nsk4.tmp\Processes.dll
- C:\R217625wabc217625\Qaekj.dll
- C:\R217625wabc217625\MUpdate.exe
- C:\R217625wabc217625\RCX5.tmp
- C:\B00T\806.exe
- %TEMP%\nsj2.tmp\Banner.dll
- C:\B00T\run.bat
- C:\B00T\BigFilePluginSetup.exe
- C:\B00T\806.exe
- C:\R217625wabc217625\Qaekj.dll
- %TEMP%\nsj2.tmp\Banner.dll
- C:\R217625wabc217625\RCX5.tmp в C:\R217625wabc217625\Qaekj.dll
- '98.##6.197.149':3201
- '98.##6.197.148':806
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: '#32770' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'